Aurora

Active
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
38 Victims
Apr 16, 2026 First Discovered
Sep 6, 2026 Last Discovered
10 Days Inactive
0% Infostealer
1/1 Sites Online
Known Locations (1)
Aur0ra Blog
u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion
Intelligence
Victims (38)

Detailed victim list temporarily unavailable

This group has 38 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.